cbcvebase.

Apple macOS vulnerabilities

3,139 known vulnerabilities affecting apple/mac_os_x.

Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191

Vulnerabilities

Page 107 of 157
CVE-2021-30716P4MEDIUMCVSS 5.9≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30716 [MEDIUM] CVE-2021-30716: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to perform denial of service.
nvd
CVE-2020-3884P4MEDIUMCVSS 6.1fixed in 10.15.42020-04-01
CVE-2020-3884 [MEDIUM] CWE-20 CVE-2020-3884: An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10. An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.
nvd
CVE-2021-30855P4MEDIUMCVSS 5.5fixed in 10.15.7v10.15.72021-08-24
CVE-2021-30855 [MEDIUM] CWE-59 CVE-2021-30855: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. An application may be able to access restricted files.
nvd
CVE-2019-8753P4MEDIUMCVSS 6.1fixed in 10.152020-10-27
CVE-2019-8753 [MEDIUM] CWE-79 CVE-2019-8753: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2005-1341P4MEDIUMCVSS 5.1v10.3v10.3.1+8 more2005-05-04
CVE-2005-1341 [MEDIUM] CVE-2005-1341: Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences. Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
nvd
CVE-2008-4222P4HIGHCVSS 7.1≤ 10.5.5v10.4.11+5 more2008-12-17
CVE-2008-4222 [HIGH] CWE-399 CVE-2008-4222: natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remot natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinite loop) via a crafted TCP packet.
nvd
CVE-2016-4721P4MEDIUMCVSS 5.9≤ 10.12.02017-02-20
CVE-2016-4721 [MEDIUM] CWE-254 CVE-2016-4721: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "IDS - Connectivity" component, which allows man-in-the-middle attackers to spoof calls via a "switch caller" notification.
nvd
CVE-2018-4153P4MEDIUMCVSS 5.9fixed in 10.142019-04-03
CVE-2018-4153 [MEDIUM] CWE-74 CVE-2018-4153: An injection issue was addressed with improved validation. This issue affected versions prior to mac An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
nvd
CVE-2010-0526P4MEDIUMCVSS 4.3v10.6.0v10.6.1+1 more2010-03-30
CVE-2010-0526 [MEDIUM] CWE-119 CVE-2010-0526: Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted genl atom in a QuickTime movie file with MPEG encoding, which is not properly handled during decompression.
nvd
CVE-2011-3246P4MEDIUMCVSS 5.0v10.7.0v10.7.12011-10-14
CVE-2011-3246 [MEDIUM] CWE-200 CVE-2011-3246: CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, wh CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL.
nvd
CVE-2004-0168P4CRITICALCVSS 10.0v10.2.8v10.3.22004-03-15
CVE-2004-0168 [CRITICAL] CVE-2004-0168: Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging." Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."
nvd
CVE-2006-4401P4MEDIUMCVSS 5.1≤ 10.4.82006-11-30
CVE-2006-4401 [MEDIUM] CVE-2006-4401: Unspecified vulnerability in CFNetwork in Mac OS 10.4.8 and earlier allows user-assisted remote atta Unspecified vulnerability in CFNetwork in Mac OS 10.4.8 and earlier allows user-assisted remote attackers to execute arbitrary FTP commands via a crafted FTP URI.
nvd
CVE-2007-0722P4MEDIUMCVSS 6.8v10.3.9v10.4+8 more2007-03-13
CVE-2007-0722 [MEDIUM] CVE-2007-0722: Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attack Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.
nvd
CVE-2004-0090P4CRITICALCVSS 10.0v10.1.5v10.2+11 more2004-12-31
CVE-2004-0090 [CRITICAL] CVE-2004-0090: Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.
nvd
CVE-2004-0513P4CRITICALCVSS 10.0≤ 10.3.42004-08-18
CVE-2004-0513 [CRITICAL] CVE-2004-0513: Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."
nvd
CVE-2009-2843P4MEDIUMCVSS 5.0v10.5.82009-12-08
CVE-2009-2843 [MEDIUM] CWE-310 CVE-2009-2843: Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for app Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers to execute arbitrary code via an applet.
nvd
CVE-2004-0092P4CRITICALCVSS 10.0v10.2.8v10.3.22004-03-03
CVE-2004-0092 [CRITICAL] CVE-2004-0092: Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact. Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.
nvd
CVE-2015-5841P4MEDIUMCVSS 5.0≤ 10.10.52015-09-18
CVE-2015-5841 [MEDIUM] CWE-74 CVE-2015-5841: The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header w The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
nvd
CVE-2020-10002P4MEDIUMCVSS 5.5fixed in 11.0.1≥ 10.14, < 10.14.6+3 more2020-12-08
CVE-2020-10002 [MEDIUM] CVE-2020-10002: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A local user may be able to read arbitrary files.
nvd
CVE-2015-5912P4MEDIUMCVSS 5.0≤ 10.10.52015-09-18
CVE-2015-5912 [MEDIUM] CWE-17 CVE-2015-5912: The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
nvd
Apple macOS vulnerabilities | cvebase